package com.tensquare.user.interceptor;

import io.jsonwebtoken.Claims;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Component;
import org.springframework.web.servlet.HandlerInterceptor;
import util.JwtUtil;

import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;

/**
 * 拦截器
 */
@Component
public class JwtInterceptor implements HandlerInterceptor {

    @Autowired
    private JwtUtil jwtUtil;

    // 无论如何都放行. 在操作中判断能不能操作
    public boolean preHandle(HttpServletRequest request, HttpServletResponse response, Object handler) throws Exception {
        System.out.println("经过了拦截器");
        // 拦截器只负责把请求头中包含token的令牌进行解析验证
        String header = request.getHeader("Authorization");
        if (header != null && !"".equals(header) && header.startsWith("Bearer ")) {
            // 得到token
            final String token = header.substring(7);
            // 对令牌进行解析 (防止解析出错 try catch)
            try {
                Claims claims = jwtUtil.parseJWT(token);
                String roles = (String) claims.get("roles");
                if (roles != null && roles.equals("admin")) {
                    request.setAttribute("claims_admin", token);
                }
                if (roles != null && roles.equals("user")) {
                    request.setAttribute("claims_user", token);
                }
            } catch (Exception e) {
                throw new RuntimeException("令牌不正确");
            }
        }
        return true;
    }

}
